{
  "threat_severity" : "Moderate",
  "public_date" : "2026-07-31T09:00:00Z",
  "bugzilla" : {
    "description" : "389-ds-base: 389-ds-base: pre-auth LDAP filter injection in CleanAllRUV status check",
    "id" : "2484802",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2484802"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
    "status" : "draft"
  },
  "cwe" : "CWE-90",
  "details" : [ "A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the attacker can extract sensitive server configuration metadata, including replication bind DNs and password storage scheme information.", "A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-check extended operation. Because the handler performs the search against cn=config with elevated replication plugin privileges and returns a boolean match result, the attacker can extract sensitive server configuration metadata, including replication bind DNs and password storage scheme information." ],
  "statement" : "A Moderate impact information disclosure flaw was found in 389 Directory Server. An unauthenticated remote attacker can exploit an LDAP filter injection vulnerability in the CleanAllRUV status-check extended operation. Red Hat products with `nsslapd-allow-anonymous-access` enabled by default are particularly susceptible.",
  "acknowledgement" : "This issue was discovered by Ian Murphy (Red Hat).",
  "package_state" : [ {
    "product_name" : "Red Hat Directory Server 11",
    "fix_state" : "Affected",
    "package_name" : "redhat-ds:11/389-ds-base",
    "cpe" : "cpe:/a:redhat:directory_server:11"
  }, {
    "product_name" : "Red Hat Directory Server 12",
    "fix_state" : "Affected",
    "package_name" : "redhat-ds:12/389-ds-base",
    "cpe" : "cpe:/a:redhat:directory_server:12"
  }, {
    "product_name" : "Red Hat Directory Server 13",
    "fix_state" : "Affected",
    "package_name" : "389-ds-base",
    "cpe" : "cpe:/a:redhat:directory_server:13"
  }, {
    "product_name" : "Red Hat Enterprise Linux 10",
    "fix_state" : "Affected",
    "package_name" : "389-ds-base",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Out of support scope",
    "package_name" : "389-ds-base",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Affected",
    "package_name" : "389-ds-base",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Affected",
    "package_name" : "389-ds-base",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Affected",
    "package_name" : "389-ds-base",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-11770\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-11770\nhttps://github.com/389ds/389-ds-base/blob/main/ldap/servers/plugins/replication/repl_extop.c" ],
  "name" : "CVE-2026-11770",
  "mitigation" : {
    "value" : "Set nsslapd-allow-anonymous-access to rootdse or off. Restrict LDAP ports to trusted networks. Monitor for extop OID 2.16.840.1.113730.3.6.8. Use strong replication manager passwords.",
    "lang" : "en:us"
  },
  "csaw" : false
}